Cyber Incident Victim: Bundesagentur für Arbeit
Date:
Mar 2025
Location:
Germany
Summary
Bundesagentur für Arbeit reported that criminals attempted to divert benefit payments by altering the bank account details of clients through compromised personal devices. In response, the agency temporarily disabled the online function for entering or changing IBAN numbers and address data to protect itself and its users. A three‑digit number of customer profiles showed unauthorized changes, but no funds were transferred to the altered accounts. The agency filed a police complaint and notified the federal data protection officer and the Federal Office for Information Security.
| CIA Posture | Motives | Tactics, Techniques & Procedures |
|---|---|---|
| Available to members | 1 motive | 1 technique |
| Threat Actors | Type | Location |
|---|---|---|
| 0 actors | Available to members | Available to members |
Description
Criminals targeted customers of the Bundesagentur für Arbeit by attempting to change their bank account information in order to divert benefit payments. The attackers gained access to client profiles and modified the IBAN numbers associated with those accounts. This activity was detected by the agency’s internal IT monitoring systems. The alteration of account details was observed as a three‑digit number of affected customer profiles.

In response, the Bundesagentur für Arbeit temporarily disabled the online function that allows users to enter or change IBAN account numbers and address details in its benefit application forms. A spokesperson in Nuremberg confirmed that the measure was taken to protect both the authority and its clients from further fraudulent attempts. The agency filed a criminal complaint with law enforcement and notified the Federal Data Protection Commissioner and the Federal Office for Information Security about the incident. According to the agency’s initial findings, no payments were actually transferred to the altered bank accounts.
As a result, the Bundesagentur für Arbeit currently cannot accept online applications for monetary benefits such as unemployment benefits. The agency has confirmed that, to date, no payments have been made to the altered bank accounts. The incident has been reported to law enforcement and the relevant data protection and IT security authorities.
